One Rewritten Memo Drains 736K USDT From Chainflip, Network Halted
Two days ago Chainflip was the backup lane for Symbiosis's frozen Bitcoin swaps. Now it's the one that's frozen.
Three key facts
Chainflip lost 736,442.17 USDT through its TRON integration. The attack began early on September 12. Over roughly 90 minutes the attacker ran the same trick eight times, six of which paid out, with later attempts roughly double the size of the first ones. Chainflip published its incident update on September 13.
The bug lived in the transaction memo. The attacker attached their own memo to TRON transactions that Chainflip's validators had already signed. The protocol read that memo as a separate swap, marked it as failed and issued a refund, so the same deposit got paid out twice.
The network is paused and users are promised to be made whole. A legitimate 115,654.41 USDT swap that was pending when the halt hit remains safe in the vault and will be released after restart. Chainflip says no other vaults were touched, the network stays down until Monday at the earliest, and this is its first critical incident involving funds taken from protocol vaults. The reimbursement method and full technical report are still pending.
WangDou's Take
This is a bank teller cashing the scribble on the back of a check as if it were a second check. The signature was real, the money was real, and the weak point was a text field meant for notes that got treated as a command.
Cross-chain protocols sell a simple story: the more chains you plug into, the more you're worth. But every new chain brings a transaction format you may not fully understand. TRON is one of the busiest highways for USDT, so everyone wants in. Whether anyone read the fine print on something as minor as the memo field just got answered in 90 minutes.
The timing stings. On September 11, Symbiosis went down and handed Bitcoin swaps to Chainflip and THORChain. A day later, the fallback sprang its own leak. The whole bridge sector is a ring of backups for each other, each one proving that nobody is actually safe.
Source: crypto.news · The Crypto Times
